CVE-2018-1524: Critical severity ibm maximo asset management vulnerability
IBM Maximo Asset Management 7.6 through 7.6.3 installs with a default administrator account that a remote intruder could use to gain administrator access to the system. This vulnerability is due to an incomplete fix for CVE-2015-4966. IBM X-Force ID: 142116.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1524?
CVE-2018-1524 is a vulnerability in IBM Maximo Asset Management 7.6 through 7.6.3 that allows a remote intruder to gain administrator access to the system.
How severe is CVE-2018-1524?
CVE-2018-1524 has a severity of 8.8 (critical).
Which IBM products are affected by CVE-2018-1524?
IBM Maximo Asset Management 7.6 through 7.6.3, IBM Maximo For Aviation 7.6.0.0 through 7.6.3.0, IBM Maximo For Life Sciences 7.6.0.0, IBM Maximo For Nuclear Power 7.6.0.0, IBM Maximo For Oil And Gas 7.5.0.0 and 7.6.0.0, IBM Maximo For Transportation 7.6.1.0 through 7.6.2.4, IBM Maximo For Utilities 7.6.0.0, and IBM SmartCloud Control Desk 7.6.0.0 and 7.6.0.1 are affected.
Is there a fix for CVE-2018-1524?
Yes, there is a fix available. Please refer to the IBM support document in the references for more information.
Where can I find more information about CVE-2018-1524?
More information about CVE-2018-1524 can be found in the IBM X-Force ID and the IBM support document in the references.